To unify customers’ data, analytics and artificial intelligence (AI) initiatives for security and compliance improvement, Comcast Technology Solutions (CTS) today unveiled the latest version of its security data fabric platform — DataBee 2.0. CTS also announced a strategic technology partnership with Databricks.
Launched in April last year, the DataBee platform is a commercially available, cloud-native security data fabric that was inspired by a security data fabric created for Comcast’s internal use and operated on Snowflake’s Data Cloud and other data lakes. DataBee brings together disparate security data from various data sources and security tools.
Internally, Comcast operates its data lake both on Snowflake’s security data lake and on Databricks. Last year, Comcast recommended customers deploy DataBee as a connected application with Snowflake, and now, the company has expanded its data lake partnerships and integrated DataBee with Databricks’ Data Intelligence Platform. Its capabilities are equally available on both platforms.
The use of the Unity Catalog and Auto Loader in Databricks is what distinguishes this partnership from Snowflake, CTS VP and GM Nicole Bucala told SDxCentral in response to questions.
“The Databricks Unity Catalog is a unified governance solution for data and AI assets that serves as a centralized location for managing data and its access. The Auto Loader automates the process of loading data from the Unity Catalog-managed data source to the Delta Lake tables within Databricks. The Auto Loader job monitors the data source for new or updated data and copies it to the appropriate Delta Lake tables,” she said. “This is in contrast with using Snowpipe to load data into Snowflake.”
“Mutual customers will now be able to easily onboard, transform and analyze critical security data alongside their enterprise data to improve cybersecurity outcomes — all from directly within the Databricks platform,” Roger Murff, VP of technology partners at Databricks, added in a statement.
Introducing DataBee 2.0In addition to the Databricks integration, Comcast also announced the general availability of DataBee 2.0, with features including active detection stream, entity resolution and security hygiene.
Bucala further elaborated on these features with use cases:
- Security hygiene: DataBee enhances configuration management database (CMDB) effectiveness by improving the accuracy, relevance and usability of asset, device and user inventory. It uses Comcast's entity resolution technology to create a unique identifier that enables asset discovery and missing owner suggestions to increase security coverage, reduce manual effort and speed up incident response.
- Asset discovery and owner discovery: DataBee continuously identifies assets, including previously unknown and orphaned ones, and fills in missing insights. It deduplicates and normalizes data to suggest owners of orphaned assets or shadow IT and uses real-time data streams to ensure up-to-date asset inventory.
- OT-IT data fusion: DataBee integrates IT and OT access logs, providing a full view of user activities across both domains through entity resolution, offering a complete perspective of a user's actions throughout their workday on both the IT and OT sides.
- Security information and event management (SIEM) aggregation: The security data fabric unifies alerts from multiple SIEMs, whether software-as-a-service (SaaS)-based or on-premises at corporate or subsidiaries, to prevent missed alerts. It combines data from indicators to tell a compelling and actionable story that might be overlooked in isolated systems.
- SIEM optimization: Enhanced with active detection streams, DataBee selectively sends only the “needles” to their SIEM, and the “haystack” through DataBee to a cost-effective data lake, so data that is traditionally discarded can now be analyzed in route while keeping the cost low.
DataBee 2.0 for Databricks is now available on Amazon Web Services (AWS), Microsoft Azure and Google Cloud Platform (GCP). The new version is also available immediately on the Snowflake Data Cloud.
Meeting SEC cyber disclosure requirementsComcast claims the DataBee 2.0 enhancements are timely in the context of evolving compliance requirements such as the PCI Security Standards Council's PCI DSS 4.0 and the Securities and Exchange Commission (SEC)’s cybersecurity disclosure rule.
PCI DSS is a global standard that provides a baseline of technical and operational requirements designated to protect payment data. Comcast offers DataBee Continuous PCI to help customers meet the new 4.0 requirements.
The SEC cybersecurity disclosure rule requires publicly traded companies to disclose “material” incidents within four business days. Bucala said the security hygiene capabilities from DataBee 2.0 can help.
“Security teams require business context to determine materiality, and our new DataBee security hygiene capability will be very helpful when it comes to identifying the asset(s) that might be the cause of — or have a significant impact on — an incident,” she said.
“Along with suggesting owners, security hygiene brings to light previously unknown assets and weaves in missing insights. Security teams can use this to triage materiality, prioritize responses and distinguish between alerts impacting critical and non-critical assets more effectively,” Bucala added.
Comments